Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Debunking the Top Cloud Security Myths
Articles

Debunking the Top Cloud Security Myths

Sarah LahavBy Sarah LahavAugust 4, 2015Updated:January 24, 20225 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Few would deny that the number of cyber-attacks – whether made public or not – is growing. Today, there are more data breaches reported in the mainstream media, not just the IT media. Cloud security, and IT security in general, are thus high on the corporate IT to-do lists for most CIOs and their teams.

However, cloud security is a peculiar beast, with the average corporate IT organization’s ability to invest in, and to address, cloud-related security threats often hampered by a plethora of cloud security myths. Some of them might be truths while others often FUD – fear, uncertainty, and doubt – deviously created to direct corporate IT purchasing decisions away from cloud.

To debunk the most common cloud security myths, we need to dig deeper into the relative levels of truth and deceit in the following three points.

1. “It’s Safer to Stay On-Premise”

There’s a perception that there are more breaches in the cloud than with on premise, however this isn’t supported by independent security research. There are a number of angles to consider here:

  • Research shows that malware is more likely to attack non-cloud systems than those in the cloud, with the route taken by hackers more likely to be through employees, and social engineering, than it is a cloud API.
  • In terms of cloud technology, hypervisors and VLANs – which are used on premise as well as in all clouds – are robust technologies that are practically impossible to crack. If there was a technology-related exploit, then it would apply to both non-cloud and cloud platforms.
  • Public clouds are also often perceived as insecure because they are “outside the corporate firewall” – but in the age of the borderless network, and with the reduced efficacy of perimeter firewalls, if you are on the network then you have an attack surface, regardless of location.

Another part of the myth is “tenant terror,” which is the phobia of sharing a cloud platform. Or more specifically, the fear of the multi-tenant resource pooling that shares compute, storage, and network amongst non-related tenants. However, this is now a mature approach, which is widely accepted by even the most risk-averse government organizations.

Verdict = Debunked

2. “Cloud Security Is Simple”

Thanks to self-service, cloud security can be perceived as simple. And an IT organization can control their public cloud security policies – including identity and access management – without being reliant on a legion of cloud service provider security staff.

However, these cloud controls aren’t the only important facets of cloud security. Visibility is probably more crucial, and where this gets difficult for organizations is in achieving a view across non-cloud and cloud systems, especially where the systems interact.

This will often lead to the purchase of a security or IT management technology to simplify cloud security. But this solving-security-by-buying-a-product approach can increase rather than decrease complexity – particularly if it’s the introduction of a tool aligned with old IT management practices that are now incompatible with the complexity of cloud.

Verdict = Debunked

3. “I’m Not in Control of My Data with Cloud”

Data sovereignty is a classic cloud myth.

It’s a mix of truth and deceit, and it’s not as simple as ensuring that your data lives in the right region – it’s also potentially affected by the location of the cloud service provider’s headquarters. If you must have your data in a specific region, or in specific regions, thankfully you can usually achieve this with a global cloud service provider – given that the leading public cloud service providers now have data center locations around the world.

However, if these providers don’t have the location you need, then a regional cloud provider might work better for you – but be aware that you’ll then have another service provider to manage and a different service experience to deal with. Also be cautious of regional providers that deliberately play on the sovereignty myth to win your business.

Then the resource pooling nature of public clouds makes storage interesting – in that you don’t control the replication of data. Anyone who believes the “I’m not in control of my data with cloud” myth will see this as a security issue – the concern being that cloud service provider staff will be using customer data for ill-gotten-gain. To alleviate this concern, understand the data-at-rest and in-transit encryption methods used – for which the provider doesn’t hold the keys – and the provider’s standard operating procedures for accessing customer information.

Verdict = Debunked

Then there is the myth that the cloud service provider is totally responsible for cloud security – but that’s another article in itself.[su_box title=”About Sarah Lahav” style=”noise” box_color=”#336588″]Sarah LahavSysAid Technologies’ first employee, Sarah is now CEO and a vital link between SysAid and its customers since 2003. As CEO, she takes a hands-on role evolving SysAid with the dynamic needs of service managers. Previously, Sarah was VP Customer Relations at SysAid and developed SysAid’s Certification Training program, advancing the teaching methods and training technology that is in place today.
Sarah holds a B.Sc. in Industrial Engineering, specializing in Information Technology from The Open University in Israel, and spends her free time with her three beautiful children.[/su_box]

Sarah Lahav

CEO, SysAid Technologies

  • Sarah Lahav
    5 New Year’s Resolutions for IT Professionals
  • Sarah Lahav
    6 Technology Predictions for 2016
  • Sarah Lahav
    Challenges of IoT in the Workplace
  • Sarah Lahav
    Future of Cloud Computing

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}